Skip to main content

Microsoft Security Practice Raises Fears

posted onMarch 12, 2005
by hitbsecnews

Microsoft Corp. is giving early versions of its software security patches to the U.S. Air Force and other organizations, a practice some experts fear could give rogue hackers important details about how to break into unprotected computers on a massive scale.

Microsoft maintains that participants in its security-testing program abide by strict rules to protect these early software patches from leaking into the Internet's underground. For added security, it doesn't provide documentation to participants about which Microsoft products might be affected and allows only for limited testing in a computer laboratory. Hackers who study such repairing patches can identify the vulnerable software and build tools to attack it. Microsoft said the program's goal is to more thoroughly test its upcoming security patches for reliability; some repairing patches from Microsoft in previous years have inadvertently disrupted computers.

"The challenge for us as a company is to make sure the updates we provide are good quality," said Stephen Toulouse, a program manager for Microsoft's Security Response Center.

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th